backup: pre-hardening baseline

This commit is contained in:
backup 2026-09-02 11:20:31 -05:00
commit 9e4c612dcb
57 changed files with 10393 additions and 0 deletions

View file

@ -0,0 +1,56 @@
package models
import (
"database/sql"
"time"
)
type User struct {
ID string `json:"id"`
Username string `json:"username"`
Email string `json:"email"`
PasswordHash string `json:"-"`
Role string `json:"role"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
LastLogin sql.NullTime `json:"last_login,omitempty"`
}
type Session struct {
ID string `json:"id"`
UserID string `json:"user_id"`
CSRFToken string `json:"-"`
CreatedAt time.Time `json:"created_at"`
ExpiresAt time.Time `json:"expires_at"`
}
type AuthResponse struct {
User *User `json:"user"`
Token string `json:"-"` // Not sent in JSON, only in cookie
}
type LoginRequest struct {
Username string `json:"username" binding:"required"`
Password string `json:"password" binding:"required"`
}
type UserRole string
const (
RoleAdmin UserRole = "admin"
RoleOperator UserRole = "operator"
RoleViewer UserRole = "viewer"
)
func (r UserRole) Can(permission string) bool {
switch r {
case RoleAdmin:
return true
case RoleOperator:
return permission != "users:write" && permission != "settings:write"
case RoleViewer:
return permission == "config:read" || permission == "traefik:read"
default:
return false
}
}